Tuesday, 2021-02-23

clarkbthe tasks are running in the context of hostA but want to lookup hostB facts00:00
clarkbI think the way you address this is with an explicit task early in the playbook to explicitly load facts for hostB00:00
clarkbmordred and pabelanger may remember running into this. I want to say for zuul base jobs?00:00
ianwhrm, why would it sometimes work and sometimes not ...?00:00
clarkbbecause it is a race between setup on hostB and starting the tasks that need the info on hostA00:01
clarkb(though this is somewhat fuzzy memory so I may have gotten the details wrong000:01
clarkbfwiw I've made a note to double check zm01.opendev.org has successfully cloned nova or openstack manuals tomorrow before doing widespread replacements00:13
clarkbas I think that is likeyl to be the only issue we'll run into at this point00:13
clarkband if it was able to successfully grab nova we should be good to replace all the zms00:13
openstackgerritMerged opendev/system-config master: Use dstat to record performance of system-config-run hosts  https://review.opendev.org/c/opendev/system-config/+/77505100:14
clarkbyay00:14
*** brinzhang_ has quit IRC00:14
*** brinzhang has joined #opendev00:14
openstackgerritSteve Baker proposed openstack/diskimage-builder master: Don't install centos-linux-release on 8-stream  https://review.opendev.org/c/openstack/diskimage-builder/+/77702700:15
openstackgerritIan Wienand proposed opendev/system-config master: service-borg-backup: preload backup server facts  https://review.opendev.org/c/opendev/system-config/+/77703200:38
clarkbnew zm01 cloned neutron without trouble and that is the third largest repo iirc00:38
ianwclarkb: ^ not sure how it sometimes works and sometimes doesn't ... is that ~ what you were thinking?00:38
*** tosky has quit IRC00:38
clarkbyes, though now I need to reread how the setup mdoule works00:39
clarkb!all means min00:40
openstackclarkb: Error: "all" is not a valid command.00:40
ianwyeah, i tested that and it seems to return ssh key facts00:40
clarkbyup looks correct to me +200:41
*** _mlavalle_1 has quit IRC00:59
openstackgerritIan Wienand proposed opendev/system-config master: gitea: fix db backup script  https://review.opendev.org/c/opendev/system-config/+/77703701:04
openstackgerritIan Wienand proposed opendev/system-config master: translate: fix backup extras match  https://review.opendev.org/c/opendev/system-config/+/77703901:12
ianwfungi: ^ i feel like the system is working :)01:12
*** ysandeep|away is now known as ysandeep|ruck01:14
fungiooh!01:15
fungiianw: the commit message on 777039 says "_extras" (plural) but the change itself adds "_extra" (singular). ask.yaml uses borg_backup_excludes_extra and isn't erroring, so i'm going to assume the diff is correct01:20
openstackgerritIan Wienand proposed opendev/system-config master: service-borg-backup: preload backup server facts  https://review.opendev.org/c/opendev/system-config/+/77703201:22
openstackgerritIan Wienand proposed opendev/system-config master: gitea: fix db backup script  https://review.opendev.org/c/opendev/system-config/+/77703701:22
openstackgerritIan Wienand proposed opendev/system-config master: translate: fix backup extras match  https://review.opendev.org/c/opendev/system-config/+/77703901:22
ianwindeed01:22
ianwand gather_subset: should be a string, not a list in 77703201:22
*** hamalq has quit IRC01:26
fungiahh, and 777032 is the fix for the race you were discussing earlier01:28
ianwit's still not clear to me how this race occurs and why it's never hit in the gate, but i think it's generally more correct01:31
openstackgerritIan Wienand proposed opendev/system-config master: gitea: fix db backup script  https://review.opendev.org/c/opendev/system-config/+/77703702:00
openstackgerritIan Wienand proposed opendev/system-config master: translate: fix backup extras match  https://review.opendev.org/c/opendev/system-config/+/77703902:00
openstackgerritIan Wienand proposed opendev/system-config master: service-borg-backup: preload backup server facts  https://review.opendev.org/c/opendev/system-config/+/77703202:04
*** stevebaker has quit IRC02:16
*** ysandeep|ruck has quit IRC02:18
*** ysandeep has joined #opendev02:19
openstackgerritMerged opendev/system-config master: translate: fix backup extras match  https://review.opendev.org/c/opendev/system-config/+/77703902:38
*** ysandeep is now known as ysandeep|away02:48
openstackgerritMerged opendev/system-config master: service-borg-backup: preload backup server facts  https://review.opendev.org/c/opendev/system-config/+/77703203:21
*** stevebaker has joined #opendev03:49
*** ysandeep|away is now known as ysandeep|ruck04:27
*** ykarel has joined #opendev04:36
openstackgerritMerged opendev/system-config master: Stop using mysqlclient ssl flag  https://review.opendev.org/c/opendev/system-config/+/72240505:00
openstackgerritIan Wienand proposed opendev/system-config master: gerrit: download latest mysql connector  https://review.opendev.org/c/opendev/system-config/+/77685705:29
openstackgerritIan Wienand proposed opendev/system-config master: [wip] gerrit : add mariadb_container option  https://review.opendev.org/c/opendev/system-config/+/77596105:29
*** marios has joined #opendev06:00
*** slaweq_ has joined #opendev06:50
*** hashar has joined #opendev07:12
*** brinzhang has quit IRC07:13
*** ralonsoh has joined #opendev07:21
openstackgerritMerged opendev/system-config master: gitea: fix db backup script  https://review.opendev.org/c/opendev/system-config/+/77703707:23
*** smcginnis has quit IRC07:30
*** smcginnis has joined #opendev07:30
*** ysandeep|ruck is now known as ysandeep|lunch07:35
*** eolivare has joined #opendev07:54
*** andrewbonney has joined #opendev08:06
*** fressi has joined #opendev08:08
*** rpittau|afk is now known as rpittau08:28
*** zoharm has joined #opendev08:30
*** ykarel_ has joined #opendev08:31
*** ykarel has quit IRC08:33
*** ysandeep|lunch is now known as ysandeep|ruck08:39
*** tosky has joined #opendev08:50
*** jpena|off is now known as jpena08:58
openstackgerritPierre Riteau proposed opendev/irc-meetings master: Cancel weekly Blazar meeting  https://review.opendev.org/c/opendev/irc-meetings/+/77578409:01
openstackgerritGuillaume Chauvel proposed opendev/system-config master: Increase autogenerated comment width to avoid line wrap  https://review.opendev.org/c/opendev/system-config/+/77144509:25
openstackgerritGuillaume Chauvel proposed opendev/system-config master: [DNM] test comment width: review without autogenerated tag  https://review.opendev.org/c/opendev/system-config/+/77179809:25
*** noonedeadpunk has quit IRC09:26
*** DSpider has joined #opendev09:26
*** noonedeadpunk has joined #opendev09:29
*** lpetrut has joined #opendev09:35
*** slaweq_ is now known as slaweq09:40
openstackgerritMerged openstack/diskimage-builder master: Don't install centos-linux-release on 8-stream  https://review.opendev.org/c/openstack/diskimage-builder/+/77702709:56
openstackgerritOleksandr Kozachenko proposed zuul/zuul-jobs master: Revert "Revert "Update upload-logs roles to support endpoint override""  https://review.opendev.org/c/zuul/zuul-jobs/+/77667710:18
*** ykarel_ is now known as ykarel10:20
openstackgerritOleksandr Kozachenko proposed zuul/zuul-jobs master: Revert "Revert "Update upload-logs roles to support endpoint override""  https://review.opendev.org/c/zuul/zuul-jobs/+/77667710:21
openstackgerritOleksandr Kozachenko proposed opendev/base-jobs master: Update post-logs playbook  https://review.opendev.org/c/opendev/base-jobs/+/77708710:25
openstackgerritGuillaume Chauvel proposed opendev/system-config master: Increase autogenerated comment width to avoid line wrap  https://review.opendev.org/c/opendev/system-config/+/77144510:46
*** rpittau is now known as rpittau|bbl11:00
*** iurygregory_ has joined #opendev11:00
*** iurygregory has quit IRC11:01
*** dtantsur|afk is now known as dtantsur11:03
*** iurygregory_ is now known as iurygregory11:06
*** smcginnis has quit IRC11:19
*** smcginnis has joined #opendev11:26
openstackgerritMartin Chacon Piza proposed openstack/project-config master: Deprecate monasca-log-api  https://review.opendev.org/c/openstack/project-config/+/77709311:39
*** brinzhang has joined #opendev11:43
openstackgerritMartin Chacon Piza proposed openstack/project-config master: Deprecate monasca-ceilometer  https://review.opendev.org/c/openstack/project-config/+/77709511:43
*** brinzhang has quit IRC11:45
*** hashar is now known as hasharLunch11:57
*** smcginnis has quit IRC12:01
*** mrunge_ has joined #opendev12:01
*** mrunge has quit IRC12:02
*** smcginnis has joined #opendev12:07
*** jpena is now known as jpena|lunch12:30
*** mrunge_ is now known as mrunge12:36
openstackgerritMerged opendev/irc-meetings master: Cancel weekly Blazar meeting  https://review.opendev.org/c/opendev/irc-meetings/+/77578412:47
*** rpittau|bbl is now known as rpittau13:01
*** jpena|lunch is now known as jpena13:33
*** zimmerry has quit IRC13:43
*** mlavalle has joined #opendev13:58
*** zimmerry has joined #opendev14:02
*** fressi has quit IRC14:06
*** fressi has joined #opendev14:07
*** fressi has quit IRC14:08
*** fressi has joined #opendev14:10
*** ysandeep|ruck is now known as ysandeep|dinner14:51
*** ykarel has quit IRC14:59
*** fressi has quit IRC15:11
*** ysandeep|dinner is now known as ysandeep|ruck15:25
clarkbzm01.opendev.org did clone nova and appears to have done so successfully. It took about 7 minutes15:44
clarkbI think that means we're good to proceed with replacing the rest of the mergers. I will work on that after meetings today15:44
clarkbalso I guess I can go ahead and clean up zm01.openstack.org. I'll try to get that done between meetings15:48
fungi7 minutes sounds about right. we used to timeout those operations at 300 and doubled it to 600 to cope with the performance change after upgrade15:51
*** sshnaidm is now known as sshnaidm|afk16:04
*** hasharLunch is now known as hashar16:22
*** lpetrut has quit IRC16:32
*** _mlavalle_1 has joined #opendev16:39
*** _mlavalle_1 has quit IRC16:41
*** mlavalle has quit IRC16:43
*** zimmerry has quit IRC16:44
*** zoharm has quit IRC16:47
*** klonn has joined #opendev16:50
*** klonn has quit IRC16:50
*** ysandeep|ruck is now known as ysandeep|away17:21
*** marios is now known as marios|out17:24
*** zimmerry has joined #opendev17:35
*** zimmerry has quit IRC17:40
*** rpittau is now known as rpittau|afk17:41
*** marios|out has quit IRC17:43
clarkbfungi: are you ok with deleting zm01.openstack.org 0dad8f01-389c-40f2-8796-57ee4901ce07 now?17:48
clarkbif so I'll get that done shortly17:48
fungiclarkb: yep, looks entirely idle, go for it17:50
*** zimmerry has joined #opendev17:53
*** zimmerry has quit IRC17:59
*** dtantsur is now known as dtantsur|afk18:00
clarkbdone18:01
clarkb#status log Deleted zm01.openstack.org 0dad8f01-389c-40f2-8796-57ee4901ce07 as it has been replaced by zm01.opendev.org18:01
openstackstatusclarkb: finished logging18:01
*** jpena is now known as jpena|off18:02
*** zimmerry has joined #opendev18:03
*** zimmerry has quit IRC18:15
*** mlavalle has joined #opendev18:20
*** eolivare has quit IRC18:29
*** lpetrut has joined #opendev18:34
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused Heat meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77718418:36
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused I18n meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77718518:37
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused LOCI meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77718618:38
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused Mistral meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77718718:39
*** lpetrut has quit IRC18:40
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused Charms meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77718818:49
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused PowerVM meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77719018:50
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused Public Cloud SIG meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77719118:51
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused Telemetry meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77719218:51
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused Vitrage meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77719318:52
openstackgerritThierry Carrez proposed opendev/irc-meetings master: Remove usused Zaqar meeting slot  https://review.opendev.org/c/opendev/irc-meetings/+/77719418:53
*** zimmerry has joined #opendev19:16
*** zimmerry has quit IRC19:16
*** zimmerry has joined #opendev19:17
*** hashar has quit IRC19:22
openstackgerritMerged openstack/project-config master: Deprecate monasca-ceilometer  https://review.opendev.org/c/openstack/project-config/+/77709519:25
*** auristor has quit IRC19:28
openstackgerritMerged openstack/project-config master: Deprecate monasca-log-api  https://review.opendev.org/c/openstack/project-config/+/77709319:29
*** andrewbonney has quit IRC19:34
*** zimmerry has quit IRC19:45
*** gmann is now known as gmann_lunch19:47
*** zimmerry has joined #opendev19:47
openstackgerritClark Boylan proposed opendev/zone-opendev.org master: Add all the new zuul mergers to dns  https://review.opendev.org/c/opendev/zone-opendev.org/+/77720419:48
openstackgerritClark Boylan proposed opendev/system-config master: Replace all the zuul mergers with new focal nodes  https://review.opendev.org/c/opendev/system-config/+/77720519:49
openstackgerritClark Boylan proposed opendev/system-config master: Cleanup zm02-08.openstack.org  https://review.opendev.org/c/opendev/system-config/+/77720619:49
clarkb206 has been marked WIP beacuse I think we want 205 in place first, turn off the mergers on the old ones, and ensure everything is happy then land 206 and delete the servers19:50
clarkbAll 7 of those new servers are up and running. I think we can land https://review.opendev.org/c/opendev/zone-opendev.org/+/777204 and https://review.opendev.org/c/opendev/system-config/+/777205 whenever people are happy with them19:52
iurygregoryclarkb, hey o/ while I was working on https://review.opendev.org/c/openstack/project-config/+/775244 a question was raised, do we need to copy-paste the definition of Backport-Candidate-label in every ACL or there is a definition of the label we should just re-use?19:55
iurygregory(not if here would be the right channel) =)19:56
clarkbiurygregory: the only labels we provide globally are code-review, verified, and approved19:56
clarkbany other backport candidates or review priority etc you have to define per acl you wish to use them in19:56
clarkbthe trouble is that things like backports dont' make sense in all repos (not even within openstack)19:58
fungianything we added centrally would end up inherited by every single project19:58
fungiwe could do multi-layer inheritance (like we once did with the api-projects acl, i think?) but that would become a struggle to keep straight too19:58
clarkbianw: fungi: I realized that I deleted zm01.openstack.org a bit early too. It should've been deleted after 777205 lands which removes it from the inventory20:00
iurygregoryclarkb, gotcha thank you very much!20:00
clarkbbut I think ansible should actually timeout the ssh connections when the host isn't there at all20:00
clarkbso its probably not urgent to land 777205 any quicker than we would normally20:00
*** auristor has joined #opendev20:05
*** gmann_lunch is now known as gmann20:07
*** LowKey has quit IRC20:09
*** LowKey has joined #opendev20:09
ianwfungi: so connecting up to the UI of a gerrit that has been started by tox20:23
ianwit is in development mode, the ui has "become"20:24
ianwbut it doesn't have the admin user20:24
fungiianw: that matches my experience with it, yes20:27
fungiand looking at the codepath, it seems to only avoid adding a default admin in dev mode if a query of the users table is nonempty20:27
fungibut we're not adding any users, so that shouldn't be the case20:28
fungiunless running gerrit a second time has a similar effect to preventing existence of the default admin20:28
*** hamalq has joined #opendev20:30
clarkbfungi: you downgraded your vote on https://review.opendev.org/c/opendev/system-config/+/777205 anything I should be looking at? or do you just want testing to complete first?20:44
clarkbalso review on https://review.opendev.org/c/opendev/zone-opendev.org/+/777204 would be great too20:44
fungiclarkb: nope, alt+1 is my shortcut for +1 in gertty but also my keybinding for switching to the system buffer in weechat. i've accidentally done that more than once :/20:48
fungithanks for catching it20:48
fungiput back to +2 again20:48
clarkbah yup I have xmonad mapped to use super instead of the default alt for similar reasons20:48
fungii went ahead and approved the dns addition, it was just adding new non-colliding records and increasing the serial. cursory review of the records added seem to match what's proposed for addition to the inventory too20:50
*** slaweq has quit IRC20:50
clarkbthanks20:50
clarkbI'm about to pop out on a bike ride but if 205 gets approved I should be back to  keep an eye on it well before itfinishes testing and zuul gets around to running the infra-prod job for zuul20:51
openstackgerritMerged opendev/zone-opendev.org master: Add all the new zuul mergers to dns  https://review.opendev.org/c/opendev/zone-opendev.org/+/77720420:53
*** knikolla has quit IRC21:11
*** knikolla has joined #opendev21:11
*** zaro has quit IRC21:11
*** zaro has joined #opendev21:13
*** zimmerry has quit IRC21:27
*** zimmerry has joined #opendev21:31
kopecmartinianw: hi, regarding the refstack and the missing 'api' part of the urls ... any chance, the urls were magically managed outside of the refstack server? by puppet or smth like that, I'm not exactly sure how the current one was exactly deployed21:36
kopecmartini'm running the server also locally and none of the server options I experimented with seem to work, it's very strange21:36
fungikopecmartin: it was/is apache mod_wsgi21:36
ianwkopecmartin: it's all ansible-ised ... whatever is on the test server we held should be the same as production21:37
openstackgerritKendall Nelson proposed openstack/project-config master: Add New Repo for StoryBoard-vue  https://review.opendev.org/c/openstack/project-config/+/77724421:38
fungiby "current one" i assumed the old/production puppeted refstack.openstack.org server21:38
kopecmartinfungi: yes21:39
kopecmartinI'll keep digging more into this pecan framework then21:39
ianwfungi: got it i think ...  "We write out the ssh host key for gerrit's ssh server which  for undocumented reasons forces gerrit init to download the  bouncy castle libs".  well the existence of that file also flips a "isNew" flag, which appears to make the site look like a not-fresh install, and prevents the admin user being created21:39
ianwi now get "RuntimeError: SSH key upload failed: <Response [400]> "Expected JSON object"21:40
ianwhttps://gerrit.googlesource.com/gerrit/+/44cd62ec1b2ef0b1d39e7d6048ae68b0091313ea/gerrit-server/src/main/java/com/google/gerrit/server/config/SitePaths.java#65 is the flag21:41
ianwschool run ... bib21:42
kopecmartinianw: that should be fixed by https://review.opendev.org/c/osf/refstack/+/77616821:42
fungiianw: aha!21:42
fungiianw: thanks a ton, i didn't even consider that's what might be triggering it. i think i should be able to work around that21:43
ianwkopecmartin: if you down the container, docker-compose pull and restart it should pick that up on the test host?21:43
fungiit's possible that "undocumented reason" is also unnecessary in 2.13. i'll play around with it a bit21:43
fungiianw: the json expectation is i think because of the content-type header being set, btw, i see zuul quickstart does text-plain to that method21:50
fungitesting that now21:50
fungiyay that works!21:51
fungii mean, not completely, the test i'm trying now fails because `ssh -p 17030 admin@127.0.0.1 gerrit create-project --empty-commit --name test/test_project` returns "fatal: --name is not a valid option" but, progress!21:52
fungigerrit create-project [NAME] [--] [--branch (-b) BRANCH] [--change-id [TRUE | FALSE | INHERIT]] [--content-merge [TRUE | FALSE | INHERIT]] [--contributor-agreements [TRUE | FALSE | INHERIT]] [--create-new-change-for-all-not-in-target (--ncfa)] [--description (-d) DESCRIPTION] [--empty-commit] [--help (-h)] [--max-object-size-limit VAL] [--new-change-for-all-not-in-target [TRUE | FALSE | INHERIT]] [--owner21:54
fungi(-o) GROUP] [--parent (-p) NAME] [--permissions-only] [--plugin-config VAL] [--reject-empty-commit [TRUE | FALSE | INHERIT]] [--require-change-id (--id)] [--signed-off-by [TRUE | FALSE | INHERIT]] [--submit-type (-t) [INHERIT | FAST_FORWARD_ONLY | MERGE_IF_NECESSARY | REBASE_IF_NECESSARY | REBASE_ALWAYS | MERGE_ALWAYS | CHERRY_PICK]] [--suggest-parents (-S)] [--trace] [--trace-id VAL] [--use-content-merge]21:54
fungi[--use-contributor-agreements (--ca)] [--use-signed-off-by (--so)]21:54
fungier, sorry for the spam21:54
fungii was going to comment on how the usage pattern for gerrit create-project is a bit complex, but i didn't realize it was quite that large21:55
fungianyway, looks like --name was likely deprecated in favor of an unkeyed argument21:55
fungiyep, that fixed it21:59
fungigetting close21:59
ianwyay!22:05
fungii think that's done it, but this was involved enough i want to break it up into a series of distinct changes22:06
fungijust so it's clear what's being altered in the testing22:07
fungiand for which reasons22:07
fungibasically it seems we can rip out the precreation of the ssh hostkeys22:08
fungiat least with 2.13, but maybe with 2.11 even22:08
fungithe addition of --dev to the init step is definitely necessary22:08
fungithe sed of the original auth type in the config file isn't needed though22:09
fungichanging to using the built-in admin account in dev mode for the tests rather than just for bootstrapping another admin user will simplify this a little bit22:10
fungihowever 2.13 does itself require changes in a couple places for the new create-project cli syntax22:10
fungifull local tox run is still in progress but seems to be passing all tests so far22:11
ianwyep, i'd agree with all that after playing.  2.13 as a lower-bound for testing seems ok?22:11
fungiyeah, i mean we can't expect people to run tests locally if modern distros' openssh won't work with the version of gerrit we're using in the tests22:12
fungibut also it's blocking us from easily testing that this works with python 3.922:13
ianwyeah, i guess it won't work on fedora by default22:13
fungigit_review.tests.test_git_review.HttpGitReviewTestCase.test_git_review_d is failing with 2.13, looks like, so that may also need adjusting22:14
fungiif this is just down to a few failing tests though, i'm still thrilled. that's way better than failing 100% of tests before you spotted the problem22:15
ianwi didn't really get my point across in https://issues.apache.org/jira/browse/SSHD-111822:15
fungi:(22:15
fungitest_uploads_with_nondefault_rebase also breaking22:16
fungii have a feeling we're relying on nuances of formatting from some responses, so i'll need to work through those22:19
fungiPassed: 109 Skipped: 1 Failed: 222:21
fungimuch better22:21
*** ralonsoh has quit IRC22:31
clarkbianw: oof ya I feel liek they dno't undersatnd that it would work if the server properly advertised the keys22:45
*** dhellmann has quit IRC22:46
*** valleedelisle has quit IRC22:46
clarkbianw: can I get a second review on https://review.opendev.org/c/opendev/system-config/+/777205 to add in a bunch of new focal mergers?22:47
clarkbthere is just enough changing with the testing and cacti and inventory etc that having another set of eyes on that would be good22:47
ianwlgtm, although i didn't check every address :)22:48
clarkbthat should be ok I copied all that out of what launch node gave me and I trust it :)22:48
*** dhellmann has joined #opendev22:48
*** valleedelisle has joined #opendev22:48
clarkbianw: re MINA maybe we should approach this from another angle. If ecdsa-foo becomes depreacted and clienst and servers need to negotiate ecdsa-new it will be the same situation I think22:51
*** tkajinam has joined #opendev22:51
clarkbthis really isn't about rsa specifically but about the server being able to communicate which algorithms for public key auth it supports22:51
ianwyeah, i mean it sort of comes down to "could you please write support for server-sig-algs"22:53
ianwif google used the ssh bits i guess it would be fixed in about 15 minutes :)22:55
clarkbwe're only failing here because openssh client falls back to rsa with sha1 if the first thing it tries fails22:56
clarkband I think that could happen with other algorithms too22:56
clarkbianw: maybe a response like "If MINA SSHD supported server-sig-algs and responded with support for rsa-sha2-256 and/or rsa-sha2-512 then fedora users would be able to authenticate with rsa keys using rsa-sha2-*. This is only failing because MINA SSHD does not respond with server-sig-algs information which forces the client to fallback to ssh-rsa which is not allowed by policy."22:59
clarkband if that doesn't help oh well22:59
clarkbtheir code supports rsa, but not in a practical way for modern ssh23:00
clarkbwhich maybe is the whole point from their end, they just want to say rsa is dead and don't use it23:00
clarkbianw: fwiw I do also think that fedora needs to upate their openssh-client to fallback to rsa-sha2-512 in this situation as well23:02
clarkbthey have disabled the fallback so they may as well try something that has a chance of working23:02
clarkbianw: completely unrelated I noticed that running the sshfp script will add host keys to known_hosts23:04
clarkbI like that as now I don't have to try and remember to do that manually23:04
clarkbhrm it could be that server-sig-algs is currently only useful for rsa beacuse all the other algorithms advertise themselves directly with their hash variants?23:10
ianwclarkb: yeah, i think the records turned out a bit less useful than i'd hoped due to the "need to flip config to trust them"23:12
clarkbya I've continued to add them as I figure they may be useful to humans still23:13
ianwyeah, i think that most every fedora 33+ is now running with "Host * PubAcceptedKeyTypes +rsa-sha2-256,rsa-sha2-512" which iirc just ends up overriding things23:14
ianwwell, through a convoluted set of operations ends up overriding the system crypto policy to fall back to the openssh default policy ...23:15
clarkbya23:18
openstackgerritMerged opendev/system-config master: Replace all the zuul mergers with new focal nodes  https://review.opendev.org/c/opendev/system-config/+/77720523:30
openstackgerritJeremy Stanley proposed opendev/git-review master: Create test projects with positional argument  https://review.opendev.org/c/opendev/git-review/+/77726023:31
* clarkb waits patiently for the deploy jobsand reviews the git-review change23:34
fungii'll probably be dribbling these in23:34
fungithough the switch to test with 2.13 will be one big blob23:35
*** roman_g has joined #opendev23:35
fungithe bit ianw found which broke the devmode account credentials (which went unnoticed since tests weren't relying on it) was necessary to make 2.11 work23:35
fungiso we really can't switch to using admin/secret without switching to 2.13, and can't switch to 2.13 without using admin/secret23:36
fungibut i'm going to try to make any changes 2.13 will need which touches tests themselves in earlier commits if 2.11 will support them23:37
fungiand then do the addition of python 3.9 in its own separate change on top of all that23:38
*** tkajinam has quit IRC23:40
*** tkajinam has joined #opendev23:40
*** roman_g has quit IRC23:45
fungiheads up, i just got privmsg spam, odds are it's someone scraping the nicklists in channels23:50
clarkbI feel left out23:54
clarkbI've remembered the othe rthing I was looking at least week was the kna1 growroot stuff23:55
clarkbspot checking logstash again I don't see any obviously broken instances23:57

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!